Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2254
Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php. NOTE: there... Read more
Affected Products : phpauction- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0780
Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters.... Read more
Affected Products : perlblog- Published: Feb. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0796
Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatemessages.php). NOTE: the provenance of this information i... Read more
Affected Products : clever_copy- Published: Feb. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0806
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified ... Read more
Affected Products : adodb- Published: Feb. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-35061
Improper initialization for the Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.... Read more
Affected Products :- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-35045
Missing Authorization vulnerability in Fat Rat Fat Rat Collect.This issue affects Fat Rat Collect: from n/a through 2.6.7.... Read more
Affected Products :- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-4087
A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS. The manipulation of the argument pad_len leads to information exposure throu... Read more
Affected Products : ipxe- Published: Nov. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-39419
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to... Read more
- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-5321
Multiple cross-site scripting (XSS) vulnerabilities in phplist before 2.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : phplist- Published: Oct. 17, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-34994
An improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to creation of an arbitrary directo... Read more
- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2764
Vulnerability in the Java SE product of Oracle Java SE (component: Advanced Management Console). The supported version that is affected is Java Advanced Management Console: 2.16. Difficult to exploit vulnerability allows unauthenticated attacker with netw... Read more
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-6096
The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity... Read more
Affected Products : .net_framework- Published: Nov. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-0692
Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript.... Read more
Affected Products : php_fusion- Published: Mar. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3200
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in ... Read more
Affected Products : utopia_news_pro- Published: Oct. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-44207
This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to capture a few seconds of audio before the microphone indicator is activated.... Read more
- Published: Oct. 04, 2024
- Modified: Mar. 25, 2025
-
4.3
MEDIUMCVE-2024-44116
The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces. There is low impact on... Read more
Affected Products : netweaver_application_server_abap- Published: Sep. 10, 2024
- Modified: Sep. 10, 2024
-
4.3
MEDIUMCVE-2024-43780
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.... Read more
- Published: Aug. 22, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2006-2955
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) New Category (newcategory) or (2) apage parameter to (a) edtalbum.asp, or the (3) cat or (4) al... Read more
Affected Products : kaphotoservice- Published: Jun. 12, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-1778
The Art Theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'arttheme_theme_option_restore' AJAX function in all versions up to, and including, 3.12.2.3. This makes it possible for authenticated attackers, wit... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2023-2285
The WP Activity Log Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.0. This is due to missing or incorrect nonce validation on the ajax_switch_db function. This makes it possible for unauthent... Read more
- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024